寻找Azure PowerShell/Azure CLI中的强身份验证及等效命令
Get-MsolUserByStrongAuthentication的替代方案 Hey there, let's break this down clearly. The Get-MsolUserByStrongAuthentication cmdlet belongs to the legacy MSOnline (Azure AD PowerShell) module, which Microsoft has deprecated in favor of the Microsoft Graph PowerShell module. Below are the equivalent ways to get the same (and more granular) info using both Microsoft Graph PowerShell and Azure CLI, plus extra context on strong authentication queries.
Azure PowerShell (Microsoft Graph)
First, make sure you have the required module installed and connected:
# Install the module (if not already installed) Install-Module Microsoft.Graph.Users.Authentication -Force -AllowClobber # Connect to Microsoft Graph with the necessary scope Connect-MgGraph -Scopes UserAuthenticationMethod.Read.All
Direct replacement for Get-MsolUserByStrongAuthentication
The legacy cmdlet returned users with strong authentication enabled. In Microsoft Graph, we check for non-password authentication methods (since these are the "strong" methods like MFA, Authenticator app, phone calls, FIDO2 keys, etc.).
To get all strong authentication methods for a single user:
Get-MgUserAuthenticationMethod -UserId john.doe@contoso.com | Where-Object { $_.AdditionalProperties["@odata.type"] -notin "#microsoft.graph.passwordAuthenticationMethod" }
To bulk list all users who have at least one strong authentication method configured:
Get-MgUser -All $true | ForEach-Object { $strongAuthMethods = Get-MgUserAuthenticationMethod -UserId $_.Id | Where-Object { $_.AdditionalProperties["@odata.type"] -notin "#microsoft.graph.passwordAuthenticationMethod" } if ($strongAuthMethods) { [PSCustomObject]@{ UserPrincipalName = $_.UserPrincipalName StrongAuthMethods = $strongAuthMethods.AdditionalProperties["@odata.type"] -replace "#microsoft.graph.", "" MethodCount = $strongAuthMethods.Count } } }
Bonus: Check user-level MFA enforcement (legacy vs modern)
Note that modern Azure AD uses Conditional Access policies to enforce MFA, rather than the old user-level "StrongAuthenticationRequirements" property. If you still need to check legacy user-level settings, you can use:
Get-MgUser -UserId john.doe@contoso.com -Property StrongAuthenticationRequirements | Select-Object UserPrincipalName, StrongAuthenticationRequirements
Azure CLI
For Azure CLI, the workflow is similar—we target user authentication methods and filter out password-based ones.
First, log in to Azure CLI:
az login
Get strong authentication methods for a single user
az ad user authentication-method list --user john.doe@contoso.com \ --query "[?@odata.type != '#microsoft.graph.passwordAuthenticationMethod']" \ --output table
Bulk list users with strong authentication enabled
Using jq for parsing (install jq if you don't have it):
# Get all user UPNs az ad user list --query "[].userPrincipalName" -o tsv | while read upn; do # Count non-password authentication methods method_count=$(az ad user authentication-method list --user "$upn" \ --query "[?@odata.type != '#microsoft.graph.passwordAuthenticationMethod'] | length" -o tsv) if [ "$method_count" -gt 0 ]; then echo "$upn has $method_count strong authentication method(s)" fi done
内容的提问来源于stack exchange,提问作者Jess

